• News/
  • https://www.bleepingcomputer.com/news/security/apache-ofbiz-rce-flaw-exploited-to-find-vulnerable-confluence-servers/

Apache OFBiz RCE flaw exploited to find vulnerable Confluence servers

BleepingComputer
·
Bill Toulas
·
Published Dec 28, 2023
·
Updated

A critical Apache OFBiz pre-authentication remote code execution vulnerability is being actively exploited using public proof of concept (PoC) exploits. Apache OFBiz (Open For Business) is an open-source enterprise resource planning system many businesses use for e-commerce inventory and order management, human resources operations, and accounting. OFBiz is part of Atlassian JIRA, a commercial project management and issue-tracking software used by over 120,000 companies worldwide. Therefore, any flaws in the open-source project are inherited by Atlassian's product. This authentication bypass flaw is tracked as CVE-2023-49070 and was fixed in OFBiz version 18.12.10, released on December 5, 2023. The issue potentially enabled attackers to elevate their privileges without authentication, perform arbitrary code execution, and access sensitive information. While investigating Apache's fix, which was to remove the XML-RPC code from OFBiz, SonicWall researchers discovered that the root cause for CVE-2023-49070 was still present. This incomplete fix still allowed attackers to exploit the bug in a fully patched version of the software. In a write-up published yesterday, SonicWall researchers demonstrate it's possible to bypass Apache's fix for the CVE-2023-49070 vulnerability when using specific credential combinations. "It was discovered while researching the root cause for the previously disclosed CVE-2023-49070," explains SonicWall's report. "The security measures taken to patch C...

Read full article

Affected Software

5 affected components
Apache OFBiz=18.12.10
Apache OFBiz=18.12.11
Apache struts
Atlassian Confluence
Apache ActiveMQ
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an exploited remote code execution vulnerability in Apache OFBiz that is being used to identify vulnerable Confluence servers.

2

What security implications are discussed in this article?

The article highlights the critical nature of the remote code execution vulnerability in Apache OFBiz, emphasizing the risk of unauthorized access to affected systems.

3

What products or software are affected by the vulnerability?

The affected products include Apache OFBiz versions 18.12.10 and 18.12.11, Atlassian Confluence, Apache Struts, and Apache ActiveMQ.

4

How is the Apache OFBiz vulnerability being exploited?

The vulnerability is being actively exploited using public proof of concept exploits that enable pre-authentication remote code execution.

5

What should organizations using the affected software do?

Organizations should promptly assess their systems for the vulnerability and apply necessary patches or updates to mitigate potential risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203